Skip to content

[ca] Update agentic CLI defaults: Claude 2.1.293, Copilot 1.0.93, Codex 0.161.0, Pi 1.1.0 #66799

Description

@github-actions

Overview

CLI/MCP version changes were detected for gh-aw default pins in workflow run §37733049509. I updated the local working tree constants and regenerated workflow locks with make recompile.

Updates detected

Component Current pin Latest stable Source Risk
Claude Code 2.1.288 2.1.293 npm @anthropic-ai/claude-code Low
GitHub Copilot CLI 1.0.90 1.0.93 npm @github/copilot; https://github.com/github/copilot-cli/releases/tag/v1.0.93 Medium
OpenAI Codex CLI 0.159.3 0.161.0 npm @openai/codex; https://github.com/openai/codex/releases/tag/rust-v0.161.0 Medium
Pi 1.0.0 1.1.0 npm @earendil-works/pi-coding-agent Medium
Playwright CLI 0.1.21 0.1.22 npm @playwright/cli; https://github.com/microsoft/playwright-cli/releases/tag/v0.1.22 Low
GitHub MCP Server v1.12.2 v2.0.1 https://github.com/github/github-mcp-server/releases/tag/v2.0.1 Medium
MCP Gateway v0.4.29 v0.4.30 https://github.com/github/gh-aw-mcpg/releases/tag/v0.4.30 Low

Threat-detect remains current at v0.5.2.

Local files updated

  • pkg/constants/version_constants.go
  • pkg/constants/version_constants_test.go
  • actions/setup/sh/install_copilot_cli.sh (regenerated default Copilot fallback)
  • .github/aw/compat.json (regenerated Copilot compat max)
  • .github/workflows/*.lock.yml via make recompile

Release and impact notes

GitHub Copilot CLI 1.0.90 → 1.0.93

  • Timeline: 1.0.91 (2026-10-01), 1.0.92 (2026-10-05), 1.0.93 (2026-10-07).
  • Breaking / migration: user-setting keys in ~/.copilot/config.json are now ignored; settings are read only from ~/.copilot/settings.json. gh-aw usage should validate any assumptions about config file location.
  • Features: copilot config settings management, pre-conversation environment picker, command sandboxing via /sandbox and --sandbox, MCP config changes between turns without restart, expanded GitHub Connector permission retry flow, enterprise permissions.limitTo network boundaries, model picker recommendations update.
  • Fixes: MCP reconnect/recovery improvements, shell output streaming, context rollover/recovery, sandbox token withholding unless configured, Windows sandbox fixes, large file/session slowdowns, authentication/session resume fixes.
  • CLI help diff: --auto-tier help changed from enumerated values to “validated against the available catalog”; copilot config --help unchanged from cached 1.0.92; copilot environment --help remains unavailable as a direct subcommand.
  • Impact: medium. This is mostly beneficial for sandbox/auth/MCP stability, but the settings-file behavior should be checked against gh-aw-generated Copilot environments.
  • Links: https://github.com/github/copilot-cli/releases/tag/v1.0.91, https://github.com/github/copilot-cli/releases/tag/v1.0.92, https://github.com/github/copilot-cli/releases/tag/v1.0.93

OpenAI Codex 0.159.3 → 0.161.0

  • Timeline: 0.160.0 (2026-10-01), 0.160.1 (2026-10-05), 0.161.0 (2026-10-07).
  • Breaking / migration: none identified in the release summaries, but 0.161.0 is a broad release with many daemon, TUI, MCP, sandbox, and authentication changes.
  • Features: older task browsing, projectless sessions with workspace defaults, opt-in Guardian context retrieval, local audio/voice settings, fork shortcut, opt-in model catalog for multi-agent context, Daybreak selection/toggle, cloud/remote/session enhancements.
  • Fixes: Windows sandbox and PowerShell fallback repairs, SQLite stall/corruption handling, provider catalog correctness, MCP OAuth/token exchange/storage updates, retry behavior, exec-server recovery, environment/sandbox metadata, local daemon diagnostics.
  • CLI help diff: top-level help unchanged from cached 0.160.1.
  • Impact: medium. Improvements are relevant to remote MCP, Windows sandboxing, and daemon stability; verify gh-aw Codex workflows after merge.
  • Links: https://github.com/openai/codex/releases/tag/rust-v0.160.0, https://github.com/openai/codex/releases/tag/rust-v0.160.1, https://github.com/openai/codex/releases/tag/rust-v0.161.0
  • PR references in release notes are external Codex PRs, e.g. Backport Windows remote MCP environment preservation to 0.160 openai/codex#51121.

GitHub MCP Server v1.12.2 → v2.0.1

MCP Gateway v0.4.29 → v0.4.30

  • Changes: debug logging in envfile handling, gh-aw workflow upgrade, centralized Rust guard labels, mixed-case repository scopes accepted in static write-sink policies.
  • Impact: low. Mixed-case repository scope handling should improve policy compatibility.
  • Docker digest resolved for ghcr.io/github/gh-aw-mcpg:v0.4.30: sha256:ab5a436a1490438db473e4e3d4c973cb1d75e3cb233fb08b73d31b42d7d18fba.
  • Release: https://github.com/github/gh-aw-mcpg/releases/tag/v0.4.30

Playwright CLI 0.1.21 → 0.1.22

  • Release date: 2026-09-28; outside the 72-hour cooldown enforced by the test metadata.
  • Fixes: run-code gets timers/fetch/URL/Buffer/crypto/AbortController/TextEncoder/TextDecoder while keeping require and process unavailable; find --filename=results.md; better dialog reporting for navigation; download/browser-close crash fix; install-browser --no-shell; webmcp-call stale tab/frame and Chromium 155+ fixes; safer bundled skill preapprovals.
  • Impact: low. Mostly bug fixes and safer command preapproval behavior.
  • Release: https://github.com/microsoft/playwright-cli/releases/tag/v0.1.22

Pi 1.0.0 → 1.1.0

  • Source: npm metadata and CLI help comparison; no public GitHub release notes were available.
  • CLI help diff vs cached 1.0.4: --tools now documents that only +name/-name entries add to or remove from defaults; examples now show pi --tools +codemode.
  • Impact: medium because this is a minor-version bump and alters documented tool-selection semantics.

Claude Code 2.1.288 → 2.1.293

  • Source: npm metadata and CLI help comparison; no public GitHub repository/release notes.
  • CLI help diff vs cached 2.1.292: no top-level help changes detected.
  • Impact: low.

Docker image audit

No pinned scanner image digest changes were detected in pkg/cli/docker_images.go.

Constant Selected tag Digest status
ActionlintImage 1.7.12 unchanged (sha256:b1934ee5f1c509618f2508e6eb47ee0d3520686341fec936f3b79331f9315667)
ZizmorImage 1.30.1 unchanged (sha256:a2eb396d886c053073405c7a980f2139ba2248ec172243cfa3841e57196e8101)
PoutineImage 1.1.6 unchanged (sha256:722a8e0999b583c1540fe2974e691032b2d9d21b9256a17965132b6bfd0081b0)
RunnerGuardImage 3.1.5 unchanged (sha256:2df426ef96d21f1622e05b21329f26bd263fc46110609cefb6afe43457613ac0)
SyftImage v1.52.0 unchanged; latest v1.54.1 skipped because the 2026-10-06 release is under the 3-day cooldown
GrypeImage v0.119.0 unchanged; latest v0.120.1 skipped because the 2026-10-06 release is under the 3-day cooldown
GrantImage v0.6.8 unchanged (sha256:172463611795f43b77302cdfbd7b3f81295492a7330e0820cfe41c3674920237)
YamllintImage latest unchanged; GitHub latest release endpoint returned 404

Validation

  • make fmt passed.
  • make recompile passed in the foreground: 328/328 workflows compiled; existing repository warnings only.
  • make test-unit passed for impacted package selection.
  • go test ./pkg/constants passed.

Next actions

  1. Review and merge the constants/lock regeneration change set.
  2. Pay special attention to Copilot CLI settings-file behavior and GitHub MCP Server v2 compatibility.
  3. Re-run the Docker image checker after the Syft/Grype releases pass the 3-day cooldown.

References:

Generated by 🔢 CLI Version Checker · pi · gpt55 · 291.2 AIC · ⌖ 18 AIC · ⊞ 11.1K · ◷

  • expires on Oct 9, 2026, 9:42 PM UTC-08:00

Activity

  1. github-actions commented on Oct 9, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #67125

    View newer issue


    This action was performed automatically by the CLI Version Checker workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    automationcookieIssue Monster Loves Cookies!dependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions